PT-2021-23977 · Humhub · Humhub
Brenu
+1
·
Published
2021-12-20
·
Updated
2022-08-09
·
CVE-2021-43847
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
HumHub versions prior to 1.10.3
HumHub versions prior to 1.9.3
Description:
HumHub is an open-source social network kit written in PHP. Prior to certain versions, it could be possible for registered users to become unauthorized members of private Spaces.
Recommendations:
For versions prior to 1.10.3, update to version 1.10.3 to resolve the issue.
For versions prior to 1.9.3, update to version 1.9.3 to resolve the issue.
Exploit
Fix
Improper Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Humhub